From 75a5eed1c0a8bf99df893e23f8fc892808394c8a Mon Sep 17 00:00:00 2001 From: barbacbd Date: Mon, 13 Jan 2025 16:15:49 -0500 Subject: [PATCH 1/2] CORS-3835: Add endpoints to the installer config ** Added the endpoints including the name and url to the install config. ** Validate the user entered data. --- pkg/types/gcp/platform.go | 21 +++++++++++++ pkg/types/gcp/validation/platform.go | 45 ++++++++++++++++++++++++++++ 2 files changed, 66 insertions(+) diff --git a/pkg/types/gcp/platform.go b/pkg/types/gcp/platform.go index 5ce97983e1a..be8c742a029 100644 --- a/pkg/types/gcp/platform.go +++ b/pkg/types/gcp/platform.go @@ -58,6 +58,27 @@ type Platform struct { // +default="Disabled" // +kubebuilder:validation:Enum="Enabled";"Disabled" UserProvisionedDNS dns.UserProvisionedDNS `json:"userProvisionedDNS,omitempty"` + + // ServiceEndpoints list contains custom endpoints which will override default + // service endpoint of GCP Services. + // There must be only one ServiceEndpoint for a service. + // +optional + ServiceEndpoints []ServiceEndpoint `json:"serviceEndpoints,omitempty"` +} + +// ServiceEndpoint store the configuration for services to +// override existing defaults of GCP Services. +type ServiceEndpoint struct { + // Name is the name of the GCP service. + // This must be provided and cannot be empty. + Name string `json:"name"` + + // URL is fully qualified URI with scheme https, that overrides the default generated + // endpoint for a client. + // This must be provided and cannot be empty. + // + // +kubebuilder:validation:Pattern=`^https://` + URL string `json:"url"` } // UserLabel is a label to apply to GCP resources created for the cluster. diff --git a/pkg/types/gcp/validation/platform.go b/pkg/types/gcp/validation/platform.go index 2ef83c77e58..8fc75d0befd 100644 --- a/pkg/types/gcp/validation/platform.go +++ b/pkg/types/gcp/validation/platform.go @@ -2,6 +2,7 @@ package validation import ( "fmt" + "net/url" "regexp" "sort" @@ -118,6 +119,7 @@ func ValidatePlatform(p *gcp.Platform, fldPath *field.Path, ic *types.InstallCon // check if configured userLabels are valid. allErrs = append(allErrs, validateUserLabels(p.UserLabels, fldPath.Child("userLabels"))...) + allErrs = append(allErrs, validateServiceEndpoints(p.ServiceEndpoints, fldPath.Child("serviceEndpoints"))...) return allErrs } @@ -161,3 +163,46 @@ func validateLabel(key, value string) error { } return nil } + +func validateServiceEndpoints(endpoints []gcp.ServiceEndpoint, fldPath *field.Path) field.ErrorList { + allErrs := field.ErrorList{} + tracker := map[string]int{} + for idx, e := range endpoints { + fldp := fldPath.Index(idx) + if eidx, ok := tracker[e.Name]; ok { + allErrs = append(allErrs, field.Invalid(fldp.Child("name"), e.Name, fmt.Sprintf("duplicate service endpoint not allowed for %s, service endpoint already defined at %s", e.Name, fldPath.Index(eidx)))) + } else { + tracker[e.Name] = idx + } + + if err := validateServiceURL(e.URL); err != nil { + allErrs = append(allErrs, field.Invalid(fldp.Child("url"), e.URL, err.Error())) + } + } + return allErrs +} + +var schemeRE = regexp.MustCompile("^([^:]+)://") + +func validateServiceURL(uri string) error { + endpoint := uri + if !schemeRE.MatchString(endpoint) { + scheme := "https" + endpoint = fmt.Sprintf("%s://%s", scheme, endpoint) + } + + u, err := url.Parse(endpoint) + if err != nil { + return err + } + if u.Hostname() == "" { + return fmt.Errorf("host cannot be empty, empty host provided") + } + if s := u.Scheme; s != "https" { + return fmt.Errorf("invalid scheme %s, only https allowed", s) + } + // Unlike AWS, the format can include a path without request parameters see + // https://cloud.google.com/storage/docs/request-endpoints as an example. + + return nil +} From 62fa0a5f742d05a272fc113edb4ce72c57288787 Mon Sep 17 00:00:00 2001 From: barbacbd Date: Tue, 14 Jan 2025 09:54:59 -0500 Subject: [PATCH 2/2] ** Added Specific endpoint names that able to be used/customized. ** Added validation for the GCP Service Endpoints. --- pkg/types/gcp/platform.go | 17 +++++ pkg/types/gcp/validation/platform.go | 18 ++++- pkg/types/gcp/validation/platform_test.go | 82 +++++++++++++++++++++++ 3 files changed, 115 insertions(+), 2 deletions(-) diff --git a/pkg/types/gcp/platform.go b/pkg/types/gcp/platform.go index be8c742a029..6db3e8845eb 100644 --- a/pkg/types/gcp/platform.go +++ b/pkg/types/gcp/platform.go @@ -6,6 +6,23 @@ import ( "github.com/openshift/installer/pkg/types/dns" ) +const ( + // CloudResourceManagerServiceName is the name and internal key for the cloud resource manager API endpoint + CloudResourceManagerServiceName = "cloudresourcemanager" + // ComputeServiceName is the name and internal key for the compute API endpoint + ComputeServiceName = "compute" + // DNSServiceName is the name and internal key for the DNS API endpoint + DNSServiceName = "dns" + // FileServiceName is the name and internal key for the file API endpoint + FileServiceName = "file" + // IAMServiceName is the name and internal key for the IAM API endpoint + IAMServiceName = "iam" + // ServiceUsageServiceName is the name and internal key for the service usage API endpoint + ServiceUsageServiceName = "serviceusage" + // StorageServiceName is the name and internal key for the storage API endpoint + StorageServiceName = "storage" +) + // Platform stores all the global configuration that all machinesets // use. type Platform struct { diff --git a/pkg/types/gcp/validation/platform.go b/pkg/types/gcp/validation/platform.go index 8fc75d0befd..bdaa4b97921 100644 --- a/pkg/types/gcp/validation/platform.go +++ b/pkg/types/gcp/validation/platform.go @@ -6,6 +6,7 @@ import ( "regexp" "sort" + "k8s.io/apimachinery/pkg/util/sets" "k8s.io/apimachinery/pkg/util/validation/field" "github.com/openshift/installer/pkg/types" @@ -77,6 +78,16 @@ var ( // userLabelKeyPrefixRegex is for verifying that the label key does not contain restricted prefixes. userLabelKeyPrefixRegex = regexp.MustCompile(`^(?i)(kubernetes\-io|openshift\-io)`) + + supportedEndpointNames = sets.New( + gcp.CloudResourceManagerServiceName, + gcp.ComputeServiceName, + gcp.DNSServiceName, + gcp.FileServiceName, + gcp.IAMServiceName, + gcp.ServiceUsageServiceName, + gcp.StorageServiceName, + ) ) const ( @@ -169,8 +180,11 @@ func validateServiceEndpoints(endpoints []gcp.ServiceEndpoint, fldPath *field.Pa tracker := map[string]int{} for idx, e := range endpoints { fldp := fldPath.Index(idx) - if eidx, ok := tracker[e.Name]; ok { - allErrs = append(allErrs, field.Invalid(fldp.Child("name"), e.Name, fmt.Sprintf("duplicate service endpoint not allowed for %s, service endpoint already defined at %s", e.Name, fldPath.Index(eidx)))) + if !supportedEndpointNames.Has(e.Name) { + allErrs = append(allErrs, field.NotSupported(fldp.Child("name"), e.Name, sets.List(supportedEndpointNames))) + } + if _, ok := tracker[e.Name]; ok { + allErrs = append(allErrs, field.Duplicate(fldp.Child("name"), e.Name)) } else { tracker[e.Name] = idx } diff --git a/pkg/types/gcp/validation/platform_test.go b/pkg/types/gcp/validation/platform_test.go index 88fde768b05..4359c8da2c1 100644 --- a/pkg/types/gcp/validation/platform_test.go +++ b/pkg/types/gcp/validation/platform_test.go @@ -153,6 +153,88 @@ func TestValidatePlatform(t *testing.T) { credentialsMode: types.MintCredentialsMode, valid: false, }, + { + name: "invalid gcp endpoint blank name", + platform: &gcp.Platform{ + Region: "us-east1", + ServiceEndpoints: []gcp.ServiceEndpoint{ + { + Name: "", + URL: "https://my-custom-endpoint.example.com/copmute/v1/", + }, + }, + }, + valid: false, + }, + { + name: "invalid gcp endpoint invalid name", + platform: &gcp.Platform{ + Region: "us-east1", + ServiceEndpoints: []gcp.ServiceEndpoint{ + { + Name: "badname", + URL: "https://my-custom-endpoint.example.com/copmute/v1/", + }, + }, + }, + valid: false, + }, + { + name: "invalid gcp endpoint duplicate name", + platform: &gcp.Platform{ + Region: "us-east1", + ServiceEndpoints: []gcp.ServiceEndpoint{ + { + Name: "compute", + URL: "https://my-custom-endpoint.example.com/compute/v1/", + }, + { + Name: "compute", + URL: "https://my-custom-endpoint.example.com/compute/v2/", + }, + }, + }, + valid: false, + }, + { + name: "invalid gcp endpoint url blank", + platform: &gcp.Platform{ + Region: "us-east1", + ServiceEndpoints: []gcp.ServiceEndpoint{ + { + Name: "compute", + URL: "", + }, + }, + }, + valid: false, + }, + { + name: "invalid scheme gcp endpoint url", + platform: &gcp.Platform{ + Region: "us-east1", + ServiceEndpoints: []gcp.ServiceEndpoint{ + { + Name: "compute", + URL: "http://my-custom-endpoint.example.com/compute/v1/", + }, + }, + }, + valid: false, + }, + { + name: "valid gcp endpoint", + platform: &gcp.Platform{ + Region: "us-east1", + ServiceEndpoints: []gcp.ServiceEndpoint{ + { + Name: "compute", + URL: "https://my-custom-endpoint.example.com/compute/v1/", + }, + }, + }, + valid: true, + }, } for _, tc := range cases { t.Run(tc.name, func(t *testing.T) {